From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9C7A828EA75; Fri, 9 May 2025 10:26:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1746786362; cv=none; b=IZkG9h47ObFhrzHtEyvlAg1ZjTrq3rdCzXh+Jz/bGXUnxr302QW8mnxfo+tFKyvLAUYIOfpZDK+1FiR00VOcppFa0i+GDyTfVzIcyxkOALLtGkR5fYaGJVz3ApfhdoHmIVhDiQoUcCF66e/ijL/yEeoQfHvChitV6b9RXse1eO0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1746786362; c=relaxed/simple; bh=fEpmDQLWLttpCZqCdebailDPLzOF/JIhp5x6zzfJN4U=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=NHjYAxOmF3IWgpwWTROCgni4lxrwjOj4X8x37b9mEB5bKbBv2ak0w+xx8UxFrmlvqCztaA8ocg3PFLeR3QV+8BLhYZkqDOXhEum+dZteB7LzU3xb0LEJw7ttnF68SN6eQpocgrMaEs8TH7vBMOl6nDxyP3Y2bDrol9b4QikYva4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=dp24dZcW; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="dp24dZcW" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 56924C4CEE4; Fri, 9 May 2025 10:25:57 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1746786362; bh=fEpmDQLWLttpCZqCdebailDPLzOF/JIhp5x6zzfJN4U=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=dp24dZcWPkjeZxnyk8bYRARgX7gTkBncKxEo1C2mnSPT+B/FZSIImctKVNTcf93s0 ZHLdewP08iN89JQVrkwiC7xvi56OuHbrGX8MffdND1nZiCA3xOgwqkpEU7q896znYJ k3wodEDEpNHzq6M7goCMMBtEl+WWNqRCB/hdigHxmAAfjuhZ4UzJ5CvJIJAmgV43n8 H48LlkenP1hjYjKSkOXNx8W0G/f9jL/WBStxdiVTHbw/kFkiufYj+HqDSrf1nU2hU6 X1WS1IdIqGFUq+XNxj9mYkAC+WKec5WoBn441COJAWCTy6JOywPq2RG3MgAXbwjQLZ sz2vSjmgK0Nuw== From: Christian Brauner Date: Fri, 09 May 2025 12:25:34 +0200 Subject: [PATCH v5 2/9] coredump: massage do_coredump() Precedence: bulk X-Mailing-List: linux-security-module@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Message-Id: <20250509-work-coredump-socket-v5-2-23c5b14df1bc@kernel.org> References: <20250509-work-coredump-socket-v5-0-23c5b14df1bc@kernel.org> In-Reply-To: <20250509-work-coredump-socket-v5-0-23c5b14df1bc@kernel.org> To: linux-fsdevel@vger.kernel.org, Jann Horn , Daniel Borkmann , Kuniyuki Iwashima Cc: Eric Dumazet , Oleg Nesterov , "David S. Miller" , Alexander Viro , Daan De Meyer , David Rheinsberg , Jakub Kicinski , Jan Kara , Lennart Poettering , Luca Boccassi , Mike Yuan , Paolo Abeni , Simon Horman , =?utf-8?q?Zbigniew_J=C4=99drzejewski-Szmek?= , linux-kernel@vger.kernel.org, netdev@vger.kernel.org, linux-security-module@vger.kernel.org, Christian Brauner , Alexander Mikhalitsyn X-Mailer: b4 0.15-dev-c25d1 X-Developer-Signature: v=1; a=openpgp-sha256; l=4911; i=brauner@kernel.org; h=from:subject:message-id; bh=fEpmDQLWLttpCZqCdebailDPLzOF/JIhp5x6zzfJN4U=; b=owGbwMvMwCU28Zj0gdSKO4sYT6slMWTI3tDa4GUz4eABDr7ALeu6FeQ9Di+dd2ynqzbnAc4zu zT/z5mt31HKwiDGxSArpsji0G4SLrecp2KzUaYGzBxWJpAhDFycAjARxTkM/wuENvycL2fi0uZ7 xsJD52+Ft7RwiINIuL1dM//TN9yb3zEyrL4UczB/vt7qH+tNRSO/CEj90GP+dSBLO3dvYvqy3fG hjAA= X-Developer-Key: i=brauner@kernel.org; a=openpgp; fpr=4880B8C9BD0E5106FC070F4F7B3C391EFEA93624 We're going to extend the coredump code in follow-up patches. Clean it up so we can do this more easily. Signed-off-by: Christian Brauner --- fs/coredump.c | 122 +++++++++++++++++++++++++++++++--------------------------- 1 file changed, 65 insertions(+), 57 deletions(-) diff --git a/fs/coredump.c b/fs/coredump.c index 281320ea351f..41491dbfafdf 100644 --- a/fs/coredump.c +++ b/fs/coredump.c @@ -646,63 +646,8 @@ void do_coredump(const kernel_siginfo_t *siginfo) goto fail_unlock; } - if (cn.core_type == COREDUMP_PIPE) { - int argi; - int dump_count; - char **helper_argv; - struct subprocess_info *sub_info; - - if (cprm.limit == 1) { - /* See umh_coredump_setup() which sets RLIMIT_CORE = 1. - * - * Normally core limits are irrelevant to pipes, since - * we're not writing to the file system, but we use - * cprm.limit of 1 here as a special value, this is a - * consistent way to catch recursive crashes. - * We can still crash if the core_pattern binary sets - * RLIM_CORE = !1, but it runs as root, and can do - * lots of stupid things. - * - * Note that we use task_tgid_vnr here to grab the pid - * of the process group leader. That way we get the - * right pid if a thread in a multi-threaded - * core_pattern process dies. - */ - coredump_report_failure("RLIMIT_CORE is set to 1, aborting core"); - goto fail_unlock; - } - cprm.limit = RLIM_INFINITY; - - dump_count = atomic_inc_return(&core_dump_count); - if (core_pipe_limit && (core_pipe_limit < dump_count)) { - coredump_report_failure("over core_pipe_limit, skipping core dump"); - goto fail_dropcount; - } - - helper_argv = kmalloc_array(argc + 1, sizeof(*helper_argv), - GFP_KERNEL); - if (!helper_argv) { - coredump_report_failure("%s failed to allocate memory", __func__); - goto fail_dropcount; - } - for (argi = 0; argi < argc; argi++) - helper_argv[argi] = cn.corename + argv[argi]; - helper_argv[argi] = NULL; - - retval = -ENOMEM; - sub_info = call_usermodehelper_setup(helper_argv[0], - helper_argv, NULL, GFP_KERNEL, - umh_coredump_setup, NULL, &cprm); - if (sub_info) - retval = call_usermodehelper_exec(sub_info, - UMH_WAIT_EXEC); - - kfree(helper_argv); - if (retval) { - coredump_report_failure("|%s pipe failed", cn.corename); - goto close_fail; - } - } else if (cn.core_type == COREDUMP_FILE) { + switch (cn.core_type) { + case COREDUMP_FILE: { struct mnt_idmap *idmap; struct inode *inode; int open_flags = O_CREAT | O_WRONLY | O_NOFOLLOW | @@ -796,6 +741,69 @@ void do_coredump(const kernel_siginfo_t *siginfo) if (do_truncate(idmap, cprm.file->f_path.dentry, 0, 0, cprm.file)) goto close_fail; + break; + } + case COREDUMP_PIPE: { + int argi; + int dump_count; + char **helper_argv; + struct subprocess_info *sub_info; + + if (cprm.limit == 1) { + /* See umh_coredump_setup() which sets RLIMIT_CORE = 1. + * + * Normally core limits are irrelevant to pipes, since + * we're not writing to the file system, but we use + * cprm.limit of 1 here as a special value, this is a + * consistent way to catch recursive crashes. + * We can still crash if the core_pattern binary sets + * RLIM_CORE = !1, but it runs as root, and can do + * lots of stupid things. + * + * Note that we use task_tgid_vnr here to grab the pid + * of the process group leader. That way we get the + * right pid if a thread in a multi-threaded + * core_pattern process dies. + */ + coredump_report_failure("RLIMIT_CORE is set to 1, aborting core"); + goto fail_unlock; + } + cprm.limit = RLIM_INFINITY; + + dump_count = atomic_inc_return(&core_dump_count); + if (core_pipe_limit && (core_pipe_limit < dump_count)) { + coredump_report_failure("over core_pipe_limit, skipping core dump"); + goto fail_dropcount; + } + + helper_argv = kmalloc_array(argc + 1, sizeof(*helper_argv), + GFP_KERNEL); + if (!helper_argv) { + coredump_report_failure("%s failed to allocate memory", __func__); + goto fail_dropcount; + } + for (argi = 0; argi < argc; argi++) + helper_argv[argi] = cn.corename + argv[argi]; + helper_argv[argi] = NULL; + + retval = -ENOMEM; + sub_info = call_usermodehelper_setup(helper_argv[0], + helper_argv, NULL, GFP_KERNEL, + umh_coredump_setup, NULL, &cprm); + if (sub_info) + retval = call_usermodehelper_exec(sub_info, + UMH_WAIT_EXEC); + + kfree(helper_argv); + if (retval) { + coredump_report_failure("|%s pipe failed", cn.corename); + goto close_fail; + } + break; + } + default: + WARN_ON_ONCE(true); + goto close_fail; } /* get us an unshared descriptor table; almost always a no-op */ -- 2.47.2